Why secret detection tools are not enough: It's not just about false positives - An industrial case study.

Why secret detection tools are not enough: It's not just about false positives - An industrial case study.
复制标题

DOI:
10.1007/s10664-021-10109-y
复制
发表时间:
2022
影响因子:
4.1
通讯作者:
Williams L
Williams L
中科院分区:
计算机科学2区
文献类型:
--
作者:
Rahman MR;Imtiaz N;Storey MA;Williams L

文献摘要

参考文献

被引文献

相似文献

在版本控制的软件项目中隐藏的秘密会给软件和服务带来安全风险。秘密检测工具可以识别代码中秘密的存在、提交变更集和项目版本控制历史记录。由于这些工具可能生成误报,因此为开发人员提供了绕过这些工具生成的警告的机制。提供这种覆盖机制有时会导致开发人员暴露软件存储库中的秘密。本文的目标是通过秘密检测工具使用数据分析的工业案例研究和对绕过工具的开发人员的调查,帮助软件安全从业者理解为什么“尽管受到工具警告,秘密仍被检查到存储库中”。警告。在本案例研究中,我们分析了一家软件公司广泛使用的签入秘密检测工具的使用数据,并调查了绕过该工具生成的警告的开发人员。从案例研究中,我们发现,尽管开发人员将50%的警告归类为误报,但由于时间限制,开发人员也绕过了警告,使用非发布项目,从版本控制历史记录中完全消除秘密的技术挑战,技术债务以及签入低风险的看法。我们提倡从业者和研究人员进一步调查我们的研究结果,以改进秘密检测工具和相关的开发实践。我们还提倡组织应该插入二级检查,就像我们研究的公司所做的那样,以捕获开发人员错误地绕过秘密检测工具的情况。
Checked-in secrets in version-controlled software projects pose security risks to software and services. Secret detection tools can identify the presence of secrets in the code, commit changesets, and project version control history. As these tools can generate false positives, developers are provided with mechanisms to bypass the warnings generated from these tools. Providing this override mechanism can result in developers sometimes exposing secrets in software repositories. The goal of this article is to aid software security practitioners in understanding why‘ secrets are checked into repositories, despite being warned by tools, through an industrial case study of analysis of usage data of a secret detection tool and a survey of developers who bypassed the tool alert. In this case study, we analyzed the usage data of a checked-in secret detection tool used widely by a software company and we surveyed developers who bypassed the warnings generated by the tool. From the case study, we found that, despite developers classified 50% of the warning as false positive, developers also bypassed the warning due to time constraints, working with non-shipping projects, technical challenges of eliminating secrets completely from the version control history, technical debts, and perceptions that check-ins are low risk. We advocate practitioners and researchers to investigate the findings of our study further to improve secret detection tools and related development practices. We also advocate that organizations should insert secondary checks, as is done by the company we studied, to capture occasions where developers incorrectly bypass secret detection tools.
DOI: 10.2307/1269599
发表时间: 1986-02-01
期刊: TECHNOMETRICS
影响因子: 2.5
作者:
BOX, GEP;MEYER, RD
通讯作者: MEYER, RD